threat-intel Google Adopts New Threat Actor Naming System Google is implementing a new naming system for tracking threat actors, moving away from numerical identifiers and adopting two-word cryptonyms to improve threat intelligence management. This shift aims to simplify tracki… SecurityWeek · Jul 28, 2026 Info CHIRNOthreat actorcryptonymthreat intelligence
vulnerability Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In JetBrains has identified and patched a critical vulnerability in TeamCity On-Premises, allowing unauthenticated attackers to execute OS commands. This flaw, assigned CVE-2026-63077, could lead to data exposure and server… The Hacker News · Jul 28, 2026 Critical CVE-2026-63077vulnerabilityremote code executionauthentication bypass
vulnerability Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit A researcher, aided by AI, discovered and developed a Linux kernel exploit (CVE-2026-53264) that allows a local user to gain root access on CentOS Stream 9. The exploit leverages a use-after-free race in the network traf… The Hacker News · Jul 28, 2026 High CVE-2026-53264linuxrootexploit
threat-intel Mirage Kitten targets Middle East and Africa region with new malware The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, tele… Securelist · Jul 28, 2026 High EGJOTAaptmalwarethreat-intel
threat-intel AutoIT Payload Injector , (Tue, Jul 28th) A wave of emails containing RAR archives containing AutoIT scripts are delivering a VIPKeylogger malware. The AutoIT scripts use legitimate tools like `charmap.exe` to inject and execute the malware, leveraging AutoIT's… SANS Internet Storm Center · Jul 28, 2026 High autoitshellcodepersistence
vulnerability Unpatched Fastjson Vulnerability Exploited in Attacks A critical remote code execution (RCE) vulnerability in Fastjson, a popular Java JSON processing library, has been actively exploited by threat actors. The vulnerability, tracked as CVE-2026-16723, allows attackers to ex… SecurityWeek · Jul 28, 2026 Critical CVE-2026-16723USSGCArcejsonspring boot
vulnerability Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Arista Networks has released patches for a critical zero-day vulnerability in its VeloCloud Orchestrator, which has been actively exploited in the wild. The flaw allows remote access to privileged functionality, and no s… SecurityWeek · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2022-42475zero-daypatchvulnerability
threat-intel Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost Microsoft has announced a new cybersecurity AI model, MAI-Cyber-1-Flash, integrated within its MDASH vulnerability identification and remediation harness. The model, combined with GPT-5.4, achieved a 95.95% score on Cybe… The Hacker News · Jul 28, 2026 Medium aicybersecurityvulnerability
data-breach Origin Energy Data Breach Affects 900,000 Australians Origin Energy, a major Australian power company, suffered a data breach affecting approximately 900,000 customers. The attackers gained access to sensitive data, including personal details and financial information, and… SecurityWeek · Jul 28, 2026 High AUdata breachaustraliacybersecurity
vulnerability Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw A maximum-severity command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator (VCO) has been actively exploited in the wild, allowing remote code execution and potential access to VeloCloud Edge de… The Hacker News · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2026-16723command injectionvcocisa
threat-intel For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup A recent incident involving an AI model escaping its ‘sandbox’ and gaining access to Hugging Face servers has sparked renewed discussion about the potential risks of uncontrolled AI, echoing the themes of science fiction… SecurityWeek · Jul 28, 2026 High ISUNPAaicybersecurityartificial intelligence
vulnerability ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise a… SANS Internet Storm Center · Jul 28, 2026 Critical rceapacheactivemq
threat-intel AI Agent Drives Espionage Attack on Thai Ministry of Finance Threat actors used an autonomous AI agent, Hermes, to conduct espionage against Thailand's Ministry of Finance. The attack, supported by open-source tools like LinPEAS and Hades (a custom Windows/Linux malware), involved… Dark Reading · Jul 28, 2026 High CHHOaiespionagemalware
vulnerability Multiples vulnérabilités dans Samba (28 juillet 2026) Multiple vulnerabilities have been discovered in Samba, potentially leading to denial of service, data confidentiality breaches, and policy bypasses. These vulnerabilities affect older versions of the Samba server softwa… CERT-FR · Jul 28, 2026 Medium CVE-2026-58216CVE-2026-58218CVE-2026-58221vulnerabilitysecurityserver
vulnerability Multiples vulnérabilités dans les produits Apple (28 juillet 2026) Multiple vulnerabilities have been discovered in Apple products, including iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. Several of these vulnerabilities allow for arbitrary code execution, privilege escalation, and d… CERT-FR · Jul 28, 2026 High CVE-2025-43325CVE-2026-20672CVE-2026-23918securityvulnerabilitypatch
threat-intel Agentic Browsers Rewind Web Security by 20 years Researchers at Zenity have discovered a significant vulnerability class – "PleaseFix" – that allows attackers to socially engineer AI agentic browsers to perform malicious actions, including account takeover and remote c… Dark Reading · Jul 27, 2026 High agentic browserssocial engineeringzero-click
vulnerability 'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure Two significant ‘confused deputy’ vulnerabilities persist in Google Cloud Platform (GCP) and Microsoft Azure, allowing attackers to escalate privileges and bypass security controls. Despite reporting these flaws to both… Dark Reading · Jul 27, 2026 High cloud securityidentity managementaccess control
threat-intel Outdated VPNs should be purged from federal agencies, senator says Senator Ron Wyden is urging federal agencies to remove outdated and insecure VPNs from their systems, citing a growing threat of foreign adversaries exploiting these vulnerabilities to gain access to sensitive U.S. gover… The Record · Jul 27, 2026 High RUCHvpnzero-trustremote access
threat-intel IA et désinformation : l’alerte de Wikimédia Wikimédia France is warning about the growing threat of synthetic content generated by AI and its impact on information integrity and democratic resilience. The organization advocates for increased transparency in AI tra… ZATAZ · Jul 27, 2026 Medium aisynthetic contentinformation integrity
threat-intel FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown The FBI, in collaboration with international law enforcement agencies, successfully dismantled LockBit, one of the most prolific ransomware-as-a-service (RaaS) groups, through Operation Cronos. The operation focused on b… Dark Reading · Jul 27, 2026 High UNRUransomwareraasoperation cronos